Lucene search

K
cveMitreCVE-2009-1721
HistoryJul 31, 2009 - 7:00 p.m.

CVE-2009-1721

2009-07-3119:00:01
CWE-824
mitre
web.nvd.nist.gov
47
cve-2009-1721
openexr
code execution
denial of service
vulnerability

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.005

Percentile

75.6%

The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.

Affected configurations

Nvd
Node
openexropenexrMatch1.2.2
OR
openexropenexrMatch1.6.1
Node
opensuseopensuseMatch10.0
OR
opensuseopensuseMatch10.3
OR
opensuseopensuseMatch11.0
Node
applemac_os_xRange<10.5.8
Node
debiandebian_linuxMatch4.0
OR
debiandebian_linuxMatch5.0
Node
canonicalubuntu_linuxMatch8.04
OR
canonicalubuntu_linuxMatch8.10
OR
canonicalubuntu_linuxMatch9.04
Node
fedoraprojectfedoraMatch10
OR
fedoraprojectfedoraMatch11
VendorProductVersionCPE
openexropenexr1.2.2cpe:/a:openexr:openexr:1.2.2:::
openexropenexr1.6.1cpe:/a:openexr:openexr:1.6.1:::

References

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.005

Percentile

75.6%